flâneur — a map of the web's best reading

Today, You Really Want a SaaS SIEM! | by Anton Chuvakin | Anton on Security | Medium

medium.com · saved by 1 readers

One thing I did not expect to see in 2021 is a lot of people complaining about how difficult their SIEM is to operate. Let’s explore this topic for the (n+1)-th time. And let me tell you … that “n” is pretty damn large since my first involvement with SIEM in January 2002 (!) — examples, examples, examples. (source, date: 2012) Before we go, we need to separate the SIEM tool operation difficulties from the SIEM mission difficulties. To remind, the mission that the SIEM is aimed at is very difficult in today’s environments. The mission also evolved a lot over the years from alert aggregation to compliance and reporting to threat detection and response support. Note that even intelligently aggregating, cleaning and normalizing lots of logs coming from a broad range of systems, from mainframes to microservices is not that easy… With that out of the way, SIEM detection challenges definitely do not mean that you need to spend hours patching a SIEM appliance, for example. Or tuning the backen

One thing I did not expect to see in 2021 is a lot of people complaining about how difficult their SIEM is to operate. Let’s explore this topic for the (n+1)-th time. And let me tell you … that “n” is pretty damn large since my first involvement with SIEM in January 2002 (!) — examples, examples, examples. (source, date: 2012) Before we go, we need to separate the SIEM tool operation difficulties from the SIEM mission difficulties. To remind, the mission that the SIEM is aimed at is very difficult in today’s environments. The mission also evolved a lot over the years from alert aggregation to

Explore this link on the map →